Dashboard · Connect

API Proxy

Forward editor-authenticated HTTP requests to external APIs with vault secrets, path allowlists, and ACL gates.

  1. Open Connect → API Proxy

    /websites/:id/proxy — add a connection (base URL + optional vault secret).

  2. Add a route

    Give it a routeId used in code (e.g. library.write), allowed methods, path allowlist, and an auth mode.

  3. Call from the SDK

    proxy.tstypescript
    await macro.proxyFetch('library.write', {
      path: '/books',
      method: 'POST',
      nodeKey: 'library.admin', // or closestPrivateBlockKey(btn)
      body: { title: 'New book' },
    })

Auth modes

  • routeAcl — same model as block ACL: allow roles or users (including everyone), deny individual users. No separate “any editor” mode — allow everyone instead.
  • capability — auto permission PROXY_<routeId>; enable it under Roles → API Proxy (no free-text key).
  • fromNode — live Node ACL for a nodeKey (caller-supplied or fixed). Pairs with Private Blocks.
Private Block + Proxy
Put admin UI inside macro/private-block, set route auth to fromNode, and pass the wrapper (or any) macro key as nodeKey. Visibility and writes share the same ACL.